NORMA eResearch @NCI Library

Using Honeypots and Deceptive Technology Approach to Improve IoT security by Preventing MITM Attacks IoT Security

Plamparambil Dinumon, Goutham Krishna (2025) Using Honeypots and Deceptive Technology Approach to Improve IoT security by Preventing MITM Attacks IoT Security. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (539kB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (511kB) | Preview

Abstract

The proliferation of resource-constrained Internet-of-Things (IoT) devices has greatly increased the potential attack surface since Man-in-the-Middle (MITM) interception is a harmful threat that is nearly invisible. Conventional IoT intrusion-detection approaches do typically operate passively and they flag anomalies only after a compromise, yet hardware-focused countermeasures neglect network-layer exploits. A slim proactive guard can tempt foes then log actions as they happen.

This dissertation designs and also implements then evaluates a medium-interaction honeypot framework that can detect MITM attacks within IoT environments. The aims specifically include emulating Telnet-based IoT services, which should attract MITM actors, also capturing and logging attacker login attempts, session commands, and packet traces. Also, the goals include assessing detection ability, attacker lag time, and system resource load.

Inside a VirtualBox sandbox totally isolated were an Ubuntu honeypot, a Kali Linux attacker, and a Windows victim machine. The Ubuntu honeypot did run Cowrie while the Kali Linux attacker did use Bettercap for ARP spoofing. Telnet session interception as well as malicious command injection simulated MITM attacks. Key behavioural metrics were extracted by analysing Cowrie JSON logs with network traffic captured using tcpdump.

Across repeated MITM attack simulations, the honeypot did successfully capture all connection attempts as well as record complete session transcripts and quantitatively measure attacker dwell-time. Average dwell-time was longer than a truthful baseline. The extension was for over six minutes now. Resource consumption remained minimal, CPU overhead stayed below 3 %, memory usage increased to approximately 18 MB, thus the solution was viable for constrained environments.

Combination of medium-interaction service emulation along with targeted MITM engagement is closing of the gap that is existing between passive anomaly detection and active opponent interaction. These findings do add to the body of knowledge on lightweight cyber-deception for IoT networks since they do show that fact.

To collect live attack traces, improve IDS signature accuracy, also strengthen firewall rules without specialized hardware, small and medium-sized enterprises can deploy the framework, a reproducible, low-cost blueprint, within virtualised labs.

The current implementation focuses on a single-protocol Telnet lure; it would be a promising direction for further research toward extending the approach to multi-protocol scenarios, encrypted traffic analysis, as well as automated lure adaptation via reinforcement learning.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Monaghan, Mark
UNSPECIFIED
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunications > Computer networks > Internet of things
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 19 Aug 2026 14:55
Last Modified: 19 Aug 2026 14:55
URI: https://norma.ncirl.ie/id/eprint/9548

Actions (login required)

View Item View Item